ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

Sonatype Uncovers Millions of Previously Hidden Open Source Vulnerabilities Through Unique Shaded Vulnerability Detection System

Fulton, Md., May 02, 2024 (GLOBE NEWSWIRE) -- Sonatype, the software supply chain optimization company, today announced it has identified 336,000 previously undetectable, “Critical” open source vulnerabilities through a new, first-of-its-kind shaded vulnerability detection capability in the Sonatype platform, that revolutionizes the identification of hidden security threats within open source code.

This industry-first data enhancement comes from a novel, Sonatype-created algorithm capable of detecting vulnerabilities in "shaded" open source files—a technique in which original code is repackaged, often making detection by traditional means impossible. Through this technique, Sonatype uncovered a previously hidden layer of risk within the software supply chain, resulting in 4.5 million additional open source vulnerabilities being found, 1.85 million with a “High” risk classification, and 336,000 having a CVSS score of 9.7+, categorized as Critical by the National Vulnerability Database (NVD) and comparable to Log4Shell in severity.

The pace of software innovation is paramount to remaining competitive, but for development teams to work efficiently, they must prioritize where to spend their time. Comprehensive intelligence on vulnerable components provides a holistic picture, improving risk management while eliminating developer waste so teams can focus on innovating at scale.  

Speaking on the announcement, Wayne Jackson, CEO of Sonatype said, "The reality is, 'good enough' is not enough when it comes to securing the open source software that underpins much of the digital world. Bad actors are constantly evolving their methods, and to help our customers stay ahead of them, we must evolve as well. Our commitment is to provide the deepest, most comprehensive insights into open source vulnerabilities, coupled with the tools and automation necessary to boost developer productivity while minimizing security risks."
This announcement is particularly important, given the recent uptick in attacks targeting the software supply chain, such as the malicious code found in the widely-used XZ utility. These recent attacks have shone a harsh light on the need for companies to adopt more sophisticated software supply chain security measures to protect against such vulnerabilities, mitigate risks within the open-source ecosystem, and safeguard organizations from large-scale attacks.

Unlike other tools, the Sonatype platform's design emphasizes comprehensiveness and precision in findings, while virtually eliminating false positives and illuminating false negatives. This ensures that teams focus only on genuine threats at the right time, thereby reducing unnecessary workload and strain on development teams. Equally important, the platform also empowers developers with automated remediation tools, enabling far more efficient and productive vulnerability resolution. 

"While no one wants to see more vulnerabilities discovered in open source, sunshine is, as they say, the best disinfectant. The key here is to prioritize the most critical, exploitable defects and to provide developers with reliable fixes that do not get in the way of innovation,” said Jackson. “We know the pressures on both developers and security teams, which is why our solutions streamline and even automate the remediation process; helping developers resolve the most critical issues while maintaining high levels of efficiency and productivity. This balance is key for driving innovation while safeguarding software integrity."

Amid the growing complexity of software supply chains, Sonatype's innovations offer optimism that developers can continue to develop innovative software, while avoiding additional security-related stress. By merging security with productivity, Sonatype dispels the notion that companies must compromise between the two. This progress highlights the potential for businesses to enhance efficiency and security, making a new era in software development and cybersecurity truly possible.

About Sonatype
Sonatype is the software supply chain optimization company. We provide the world’s best software supply chain optimization technology and intelligence, empowering enterprises to create and maintain secure, quality, and innovative software at scale. As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open source software, we are software pioneers and our open source expertise is unmatched. We empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development. More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains. To learn more about Sonatype, please visit www.sonatype.com.

Attachment


Elissa Walters
Sonatype
ewalters@sonatype.com

Recent Quotes

View More
Symbol Price Change (%)
AMZN  229.67
+3.39 (1.50%)
AAPL  276.97
+1.05 (0.38%)
AMD  206.13
-8.92 (-4.15%)
BAC  52.48
+0.55 (1.06%)
GOOG  323.64
+5.17 (1.62%)
META  636.22
+23.17 (3.78%)
MSFT  476.99
+2.99 (0.63%)
NVDA  177.82
-4.73 (-2.59%)
ORCL  197.03
-3.25 (-1.62%)
TSLA  419.40
+1.62 (0.39%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.